Effective date: 20 July 2026 · Last updated: 18 July 2026
This Privacy Policy explains how ETECHFLOW LTD ("we", "us", "our"), a company registered in England and Wales with registered office in Wolverhampton, United Kingdom (company number: 17286927), collects, uses, and protects information when you use the Diet Match mobile application (the "App") and related services (together, the "Service").
Diet Match helps people manage overlapping medically-restricted diets. Because it processes information about your health conditions, this policy pays particular attention to how that data — which UK GDPR classifies as "special category data" — is handled, in addition to the ordinary personal data every app collects.
Data controller: ETECHFLOW LTD, Office 1306, 85 Dunstall Hill, Wolverhampton, WV6 0SR, United Kingdom, Wolverhampton, United Kingdom.
Data protection contact: support@dietmatch.co.uk — for any question about this policy or to exercise the rights described in Section 9.
If ETECHFLOW LTD is required to appoint a Data Protection Officer under UK GDPR Article 37 (to be confirmed as part of the DPIA process — see the separate DPIA document), that person's contact details will be added here.
2.1 Account information
Email address and, if you sign in with Apple or Google, the identifier and name those providers share with us.
Country (used to apply the correct in-app disclaimer text and store-disclosure language for your region).
2.2 Health and diet information (special category data)
This is the core data the App needs to function, and it receives the highest level of protection under this policy:
The medical condition(s) you tell us you manage (from a fixed list: chronic kidney disease and its stage, Type 1 or Type 2 diabetes, coeliac disease, and low-sodium/cardiac diets).
Allergies or intolerances you add to your profile.
Symptom or reaction journal entries you choose to log (date, severity, and any free-text notes).
Results from the "Can I eat this?" scanner (Premium+): the food or menu text you scan and the compliance verdict returned — the photo itself is processed on your device and is never uploaded to us (Section 2.5).
We only ask for this information after you give a separate, specific, opt-in consent during onboarding — it is not bundled into your acceptance of these Terms or this Policy. You can withdraw that consent at any time in Settings, which deletes your diet profile (Section 8).
2.3 Usage and technical data
App interaction data (e.g. which screens you use) and device/OS information, used to fix bugs and understand feature usage.
Crash and performance diagnostics.
2.4 Subscription and purchase data
Subscriptions are purchased and billed entirely through the Apple App Store or Google Play. We do not receive or store your payment card details. We receive from Apple/Google (or our subscription-management provider) only the information needed to know which tier you're entitled to and when it renews or expires.
2.5 Camera and OCR data
The "Can I eat this?" scanner processes photos on your device using on-device text recognition (Apple Vision on iOS, ML Kit on Android). The photo is not transmitted to our servers — only the extracted text is sent, to be matched against food data and your diet profile.
UK GDPR requires two layers of legal basis for the health-related data described in Section 2.2, because it is special category data under Article 9:
An Article 6 basis — for the account and app-functionality data generally, this is performance of our contract with you (providing the Service you signed up for) or, for optional features, your consent.
An Article 9 condition, in addition — for your diet, condition, and symptom data specifically, this is Article 9(1)(a): your explicit, informed consent, captured as the separate onboarding step described in Section 2.2.
Where we rely on consent (Article 6(1)(a) or Article 9(1)(a)), you may withdraw it at any time; this does not affect the lawfulness of processing carried out before withdrawal.
To generate meal plans, recipes, and grocery lists compliant with your combined dietary restrictions.
To operate the food/menu scanner and return a compliance verdict.
To let you log and export a symptom/reaction history to share with your own healthcare provider.
To provide customer support and respond to your requests.
To maintain the security and integrity of the Service.
To meet our legal and regulatory obligations.
We do not use your health or diet data for advertising, and we do not sell it. We do not permit any third-party advertising or data-mining SDK to access condition-level data, consistent with Apple's and Google's health-app policies.
We share personal data only with the following categories of recipient, each acting under a data processing agreement where they process data on our behalf:
Recipient
What they receive
Purpose
Supabase (cloud hosting & database; EU / Ireland region)
All app data (encrypted at rest for health-related fields)
Hosting the Service
Subscription management platform (e.g. RevenueCat or equivalent)
Subscription/entitlement status, device/platform identifiers
Managing App Store/Google Play subscriptions
USDA FoodData Central (US government, public API)
No personal data — we query public nutrient data only
Powering the nutrient database behind meal plans
Apple Inc. / Google LLC
Purchase and subscription events; app store analytics per their own policies
Payment processing, app distribution
First-party analytics on our own servers (no third-party analytics or advertising SDK)
De-identified usage/crash counts and categories only — never condition-level health data, and never sent to any third party
Improving app stability and features
We do not otherwise share your personal data with third parties for their own marketing purposes. We may disclose information where required by law, to protect our legal rights, or in connection with a merger, acquisition, or sale of assets (in which case you will be notified before your data becomes subject to a different privacy policy).
Where any recipient in Section 5 is located outside the UK, we rely on an appropriate transfer mechanism recognised under UK GDPR (such as the UK's International Data Transfer Addendum to the EU Standard Contractual Clauses, or a UK adequacy regulation). We prefer providers offering UK/EU data residency for health-related tables specifically, to keep this analysis straightforward — see Launch Spec Section 4.2. Health-related data is hosted in the EU (Ireland). As the UK recognises the EEA as providing adequate protection, EU–UK transfers rely on that adequacy; any transfer to a recipient outside the UK/EEA relies on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
We keep your account and diet-profile data for as long as your account is active. If you delete your account, we delete your diet profile, symptom logs, and scan history within 30 days, except where we must retain limited records for legal, accounting, or dispute-resolution purposes. You can request deletion at any time from Settings or by contacting us (Section 9).
Under UK GDPR, you have the right to:
Access the personal data we hold about you.
Correct inaccurate or incomplete data.
Request erasure of your data ("right to be forgotten").
Restrict or object to certain processing.
Receive your data in a portable format.
Withdraw consent at any time, where processing is based on consent.
Complain to the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data lawfully.
To exercise any of these rights, contact us using the details in Section 1. We will respond within one month, as required by UK GDPR.
Diet Match is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
We apply technical and organisational measures appropriate to the sensitivity of the data we process, including encryption of health-related fields at rest, encryption in transit, row-level access controls so your health data is only accessible by you, and restricted internal access. No system is completely secure, and we cannot guarantee absolute security.
Diet Match is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. It is a planning and information tool, not a substitute for professional medical or dietetic advice. Always consult a qualified healthcare professional about your diet and any medical condition. See the full disclaimer in our Terms of Service.
We may update this policy from time to time. If we make material changes, we will notify you in the App or by email before the change takes effect. The "Last updated" date at the top of this policy shows when it was last revised.
ETECHFLOW LTD, Office 1306, 85 Dunstall Hill, Wolverhampton, WV6 0SR, United Kingdom, Wolverhampton, United Kingdom. Email: support@dietmatch.co.uk.